Security Tools
147 best Security tools and apps, curated and ranked by community upvotes on ProductCool. Updated daily as new Security products launch.
PortAura is a native macOS utility that shows which processes are listening on which ports, where they’re exposed, and what has changed since your trusted baseline. It helps you understand local services without digging through Terminal commands. Everything runs locally on your Mac.
Your Axari AI twin understands your security world, works across your tools and teams, and keeps work moving until it is actually done. Assign it a goal, let it work proactively, or give it recurring responsibilities – all from within Slack or MS Teams. Attackers aren't going to use less AI, neither should you. You + your AI twin = indefatigable.
Your team has done months of work with AI assistants. Claude Code, Codex, Cursor and OpenCode each keep a full record of it, in its own format, and none can read the others. One command reads what they wrote and turns it into one searchable history. Passwords come out before anything leaves your computer. Your assistant searches it itself, so it stops asking what you decided last month. It also finds keys that leaked into old chats, and checks which still work.
Harden AIF is a free, local security tool for AI coding agents. Its post-trained model checks tool calls before they run, using your request and session context. It beat frontier models on key agent-security benchmarks, while keeping your repo and tool output on your machine.
Replay pentests your web app on every QA pass now: injection flaws, broken access control, IDOR, the stuff AI-generated code tends to miss. Findings come back as full bug reports, evidence and suggested fix included. Schedule it daily or weekly and skip the "remember to test" step. You wake up to a queue of bugs already triaged. Same projects also test against dev, staging, prod, and localhost, so you're not maintaining separate QA setups per environment.
Gemini 3.8 Flash and Gemini 3.8 Flash Cyber bring next-generation intelligence to agentic workflows and cybersecurity. Built for long-horizon coding, multi-step reasoning, autonomous tasks, and vulnerability detection, they deliver stronger performance at Flash speed and low cost.
Gemini 3.8 Flash and Gemini 3.8 Flash Cyber bring next-generation intelligence to agentic workflows and cybersecurity. Built for long-horizon coding, multi-step reasoning, autonomous tasks, and vulnerability detection, they deliver stronger performance at Flash speed and low cost.
ipatool is a command-line utility that enables developers and researchers to search for and download app packages (IPA files) from the official App Store. It solves the problem of needing to manually extract or acquire these packages for tasks like security research, compatibility testing, or archival purposes. This tool is primarily for security researchers, iOS developers, and archivists who require direct access to app binaries outside of a standard iOS device.
Hacktron already reviews your code, detects real vulnerabilities, and learns from your feedback. Now it fixes the vulnerabilities too. With automations, Hacktron acts like a real engineer, validating security issues, eliminating false positives, and implementing patches. Set the rules once, and Hacktron performs an action on every trigger. The first action is remediation - Hacktron validates the finding dynamically, and hands your team a well-tested, ready-to-review fix.
Decawork is how IT teams take employee-built AI agents live and control every one of them from one place. An employee builds an agent on Claude Code, Codex, or any vibecoding tool; we take it in, put it on company accounts, and run it as a company asset. From there, IT team manages the agent like an employee: access, oversight, retirement.
AI-Infra-Guard is a comprehensive red teaming platform designed to secure modern AI ecosystems. It identifies vulnerabilities across AI agents, skills, MCP servers, underlying infrastructure, and LLM jailbreak risks. This platform is essential for security teams, AI developers, and enterprises deploying AI to ensure their systems are robust and resilient against emerging threats.
Prized lets ops, support, and finance teams build and ship secure internal tools with AI. Company data pre-connected and scoped, an audit trail on every access, one-click deploy behind your company sign-in.
This is an open-source library of 734 structured cybersecurity skills following the agentskills.io standard. It solves the problem of AI agents lacking domain-specific, actionable cybersecurity knowledge by providing pre-built, framework-mapped workflows. It's designed for developers and security professionals using AI coding assistants like Claude Code, GitHub Copilot, and Cursor to enhance their agents' security capabilities.
Strix is an open-source AI penetration testing platform that continuously finds and fixes vulnerabilities across your code, APIs, web apps, and cloud infrastructure. It automates security testing on every deploy, providing proof-of-exploit for findings and even generating merge-ready fix suggestions. It's designed for security and development teams who need to secure their full application stack proactively and at scale.
Execlave is an AI Agent Governance and Enforcement platform (runtime AMP) that sits between autonomous agents and your real systems, enforcing policy before every action instead of after incidents. It gives platform and security teams runtime policy enforcement, kill switches, and audit-ready trails so every agent action is authorized, traceable, and compliant with SOC 2, EU AI Act, ISO 27001, and other enterprise frameworks.
Worried about identity theft? Protect your personal info with dark web monitoring and automated data removal. See what’s exposed and delete it today.
Authentik is a self-hosted, open-source identity provider that replaces reliance on third-party authentication services. It solves the problem of securing sensitive user data by giving organizations full control over their authentication infrastructure, with flexibility for any environment. It's designed for businesses and developers who prioritize security, transparency, and customization in their identity and access management.
Shieldstral is a 3B open-weight multimodal guardrail from Mistral. Define safety policies in natural language at inference time. It evaluates text, images, or both from a single token output, running locally on a single 16GB GPU.
Stop selling abstract "AI safety". Enterprises buy operational control. Aegisora is an open-source, zero-latency proxy layer built for AppSec teams. Intercept malicious LLM actions, enforce least-privilege API access, mask PII on the fly, and generate readable audit logs for autonomous agents—without the bloated middleware.
The person on your next video call might not be real. With Halo you don't have to guess. Halo secures your Zoom, Teams, or Google Meet call live and flags synthetic faces the moment it detects one, entirely on your device. Deepfake video calls are already being used to scam people and businesses around the world, it's just that most people have no way to tell. From confirming who you're hiring to confirming who you're wiring money to, Halo catches it before it costs you.
The AI Agent Governance Toolkit provides a comprehensive framework for securing and managing autonomous AI agents in production. It solves critical challenges in agentic AI, including policy enforcement, identity management, sandboxed execution, and reliability, directly addressing the OWASP Agentic Top 10 security risks. It is designed for developers, platform engineers, and security teams building and deploying reliable, enterprise-ready AI agent systems.